Healthy and suitable to use, with a small maintenance risk. It has frequent recent releases, active organization backing, a matching repository, tests, and a clear license; recent commits all come from one contributor and the repository lacks security policy and scanning.
82%
Total Score
88
100
94
80
All 3 recent commits came from one contributor, so maintenance depends heavily on a single active person. Organization backing provides some handoff capacity, but this remains a real continuity risk.
Composer and Phing build tooling are present, but no security-scanning tools were detected. The build setup is positive while security-process visibility is limited.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The single workflow has no top-level token permissions declaration. No write permissions or other dangerous workflow behavior were detected, but explicit least-privilege configuration would provide better supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neuron-php/core Version 0.8.* | — | — |
neuron-php/logging Version 0.9.* | — | — |
neuron-php/patterns Version 0.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.